A method and system for managing network data in a cognitive center

By using language description and threshold secret sharing technology, the network data of the intelligent computing center is divided into multiple shadow segments, which solves the single point of failure and security risks of traditional intelligent computing centers, achieves higher security and flexibility, and improves the reliability and stability of data management.

CN120639280BActive Publication Date: 2026-04-07YOU FENG KE JI YOU XIAN GONG SI +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Traditional intelligent computing center network data management suffers from single point of failure risks, is easily targeted by attacks, and lacks flexible and sophisticated security protection mechanisms, especially in the process of sensitive information management and sharing, where there is a risk of leakage.

Method used

Employing language description and threshold secret sharing techniques, secret data is formally described, divided into multiple shadow fragments, and assigned to different protocol participants. Data can only be reconstructed when the minimum number of shadow fragments is reached, combined with hierarchical and graphical structure management.

Benefits of technology

It improves the security and flexibility of network data management, reduces the risk of data leakage, enhances fault tolerance, reduces the risk of single points of failure, and improves the stability and continuity of data services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639280B_ABST
    Figure CN120639280B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network data management, in particular to a kind of intelligent calculation center network data management method and system, method includes: obtaining original data set containing original information as input, original data set contains secret data needing to be hidden;Evaluate original data set, determine secret data needing to be hidden from original data set, obtain secret data set;Secret data set is described in language, extract the key features of secret data, generate corresponding formal description structure;Based on formal description structure and the key features of secret data, select the parameters of threshold secret sharing scheme, determine the total number of protocol participants n and the minimum shadow fragment number m required for secret data reconstruction, and select the allocation mode of secret data as equal allocation or privileged allocation one;Execute threshold secret sharing scheme, divide secret data set into n shadow fragments according to formal description structure, and distribute the n shadow fragments to n protocol participants respectively;When secret data needs to be recovered, collect no less than m shadow fragments, and combine at least m shadow fragments according to formal description structure to reconstruct original secret data;The application realizes fine management and security protection of network data by combining language description and threshold secret sharing technology.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network data management, and particularly relates to a method and system for network data management of an intelligent computing center. BACKGROUND

[0002] With the rapid development of artificial intelligence, big data, cloud computing and other technologies, intelligent computing centers have gradually become an important infrastructure for digital transformation in various industries. Intelligent computing centers provide support for large-scale computing tasks and intelligent applications by aggregating and managing massive amounts of network data. However, as the scale of network data rapidly expands, the complexity and security of data management have become increasingly prominent.

[0003] In traditional network data management of intelligent computing centers, a centralized data storage and management mode is often used, which has security risks such as single point of failure and being an easy target for network attacks. In addition, when facing network data involving sensitive or confidential information, traditional data management solutions usually only use basic encryption methods for protection, lacking more flexible, fine-grained and secure management mechanisms, making data vulnerable to leakage during sharing and storage.

[0004] To solve the above problems, there is an urgent need to propose a more secure and flexible data management method to make intelligent computing centers have higher security, flexibility and fault tolerance in network data management and sharing. SUMMARY

[0005] In view of the above technical problems, the present application provides a method and system for network data management of an intelligent computing center, which realizes fine-grained management and security protection of network data by combining language description and threshold secret sharing technology, thereby effectively addressing security risks and management bottlenecks in network data management of intelligent computing centers.

[0006] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.

[0007] According to an aspect of the present application, a method for network data management of an intelligent computing center is provided, the method comprising:

[0008] Obtaining an original data set containing original information as input, the original data set containing secret data to be concealed;

[0009] Evaluating the original data set to determine secret data that needs to be concealed from the original data set, obtaining a secret data set;

[0010] Performing language description on the secret data set, extracting key features of the secret data, and generating a corresponding formal description structure;

[0011] Based on the formal description structure and the key features of the secret data, parameters of a threshold secret sharing scheme are selected, the total number of protocol participants n and the minimum number of shadow fragments m required for reconstruction of the secret data are determined, and the allocation method of the secret data is selected as equal allocation or privileged allocation;

[0012] The threshold secret sharing scheme is executed, the secret data set is divided into n shadow fragments according to the formal description structure, and the n shadow fragments are respectively allocated to n protocol participants;

[0013] When the secret data needs to be recovered, no less than m shadow fragments are collected, and the original secret data is reconstructed according to the formal description structure at least m shadow fragments.

[0014] Further, in the evaluation of the original data set, it also includes:

[0015] The secret data to be hidden is extracted from the original information data set, and irrelevant data is excluded or inserted as noise data to interfere with the true meaning of the secret data.

[0016] Further, when the secret data set contains multiple secret data, if multiple secret data have similar meanings, a unified language description is used; if the meanings of multiple secret data are different, each secret data is described independently; language description is realized by formal grammar, and the formal grammar is selected from one of sequential grammar, tree grammar or graph grammar.

[0017] Further, in the equal allocation method, each protocol participant obtains a secret shadow fragment with equal rights; in the privileged allocation method, at least one protocol participant is designated as a privileged participant and is allocated a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction process of the secret data.

[0018] Further, the threshold secret sharing scheme is executed in a hierarchical multi-level structure environment, and the protocol participants are distributed in multiple levels including organization layer, fog computing layer and cloud layer. The protocol participants in each level obtain the secret shadow fragments of the corresponding level, thereby realizing the distribution and management of the secret data in the multi-level structure.

[0019] Further, when the formalized description structure is a tree structure, the secret data set is divided into a plurality of hierarchical sub-secret nodes, each sub-secret node corresponding to a part of the secret data set, the connection relationship between each sub-secret node representing the combination order of each part of the secret data, and the sub-secret nodes of different levels are distributed to the protocol participants of the corresponding levels; when the formalized description structure is a graph structure, the secret data set is divided into a plurality of secret parts and mapped to the nodes of the graph structure, each node corresponding to a part of the secret data set, each node being connected through undirected edges to represent the association relationship between the secret parts, and each node corresponding secret part is distributed to different protocol participants as a shadow segment.

[0020] Further, when the secret data is image data, a language description based image threshold secret sharing scheme is executed, including:

[0021] generating a formalized graph structure according to the key features of the image data, dividing the image data into a plurality of shadow segments, each shadow segment corresponding to a node in the graph structure;

[0022] determining the minimum number of combinations of shadow segments required to reconstruct the image data through the association relationship between the nodes in the graph structure, and distributing the shadow segments to different protocol participants, so that the original image data can be recovered when no less than the minimum number of combinations of shadow segments are collected.

[0023] According to a second aspect of the present disclosure, a smart center network data management system is provided, the system comprising:

[0024] an acquisition module for acquiring an original data set containing original information as input, the original data set containing secret data to be concealed;

[0025] an evaluation module for evaluating the original data set, determining the secret data to be concealed from the original data set, and obtaining a secret data set;

[0026] a language description module for language description of the secret data set, extraction of key features of the secret data, and generation of a corresponding formalized description structure;

[0027] a scheme selection module for selecting parameters of a threshold secret sharing scheme based on the formalized description structure and the key features of the secret data, determining the total number of protocol participants n and the minimum number of shadow segments m required for reconstruction of the secret data, and selecting the distribution method of the secret data as one of equal distribution or privileged distribution;

[0028] A shared execution module is configured to execute the threshold secret sharing scheme, divide the secret data set into n shadow fragments according to the formal description structure, and distribute the n shadow fragments to n protocol participants respectively.

[0029] A data recovery module is configured to collect no less than m shadow fragments when it is necessary to recover the secret data, and combine the at least m shadow fragments according to the formal description structure to reconstruct the original secret data.

[0030] The technical solution of the present disclosure has the following beneficial effects:

[0031] The security of network data management is improved. The sensitive information is divided into multiple shadow fragments by the threshold secret sharing technology, and the data can be reconstructed only when a predetermined number of shadow fragments are reached, which greatly reduces the risk of data leakage. The flexibility and refinement of data management are enhanced. The key features of different data can be clearly defined and distinguished by using language description methods, making the sharing and management of data more accurate. The fault tolerance of the system is improved. Even if part of the shadow fragments are lost or damaged, data reconstruction can still be completed through other shadow fragments, significantly improving the reliability of data recovery. The single point failure risk caused by centralized storage of data is reduced. The distributed shadow management strategy significantly improves the stability and sustainability of data services of the intelligent computing center. BRIEF DESCRIPTION OF DRAWINGS

[0032] Figure 1 A flowchart of an intelligent computing center network data management method in an embodiment of the present disclosure;

[0033] Figure 2 A structural block diagram of an intelligent computing center network data management system in an embodiment of the present disclosure;

[0034] Figure 3 A terminal device for implementing an intelligent computing center network data management method in an embodiment of the present disclosure;

[0035] Figure 4 A computer readable storage medium storing an intelligent computing center network data management method in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0036] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations can be implemented in any number of manners, and are not limited to the examples described herein; rather, examples are provided so that this disclosure will be thorough and complete, and will fully convey the concept of example implementations to those skilled in the art. Described features, structures, or characteristics can be combined in any suitable manner in one or more implementations. In the following description, numerous specific details are provided to give a thorough understanding of implementations of the disclosure. One skilled in the relevant art will recognize, however, that the aspects of the disclosure can be practiced without one or more of the specific details, or with other methods, components, devices, steps, etc. In other instances, well-known structures have not been described in detail so as not to obscure aspects of the disclosure.

[0037] Furthermore, the accompanying drawings are only schematic and are non-limiting examples. Like references signs refer to like parts throughout the several views. Some of the blocks in the drawings are functional blocks that represent functions implemented by software, hardware, or a combination of software and hardware. Some of the blocks in the drawings represent functional entities that can be implemented in software, hardware, or a combination of software and hardware.

[0038] The present application provides a product intelligence center network data management method. Referring to Figure 1 FIG. 1 shows a flowchart of an intelligence center network data management method provided by an embodiment of the present application. The method can be applied in electronic devices such as personal computers and servers. The method can be executed by a device, which can be implemented by software and / or hardware. The method can specifically include the following steps S101-S106:

[0039] In step S101, a raw data set containing raw information is acquired as input, and the raw data set contains secret data to be concealed.

[0040] In this step, data sets to be processed are collected from external data sources. These data include important sensitive information such as personal privacy data, enterprise confidential data, or strategic information.

[0041] In step S102, the raw data set is evaluated, and secret data to be concealed is determined from the raw data set, obtaining a secret data set.

[0042] In the evaluation of the raw data set, secret data to be concealed is extracted from the raw information data set, and irrelevant data is removed or inserted as noise data to interfere with the true meaning of the secret data.

[0043] Specifically, a comprehensive evaluation is performed on the acquired original data set in step S102, and the main purpose is to identify secret data of important value for protection from the complex data, so as to form a secret data set and lay a foundation for subsequent security processing. Secret data extraction can be automatically or semi-automatically filtered out from the original data set by preset rules, keyword matching, pattern recognition, machine learning algorithms or manual annotation, etc. These sensitive information includes user privacy, business secrets, strategic plans, financial data and other contents that need to be strictly protected. The extracted secret data will be summarized as a secret data set. In order to improve the efficiency of data management and protection effect, the data unrelated to secret data or with lower security risk is removed to reduce the subsequent processing burden.

[0044] In step S103, the secret data set is described in language, the key features of the secret data are extracted, and the corresponding formal description structure is generated.

[0045] When the secret data set contains multiple secret data, if the multiple secret data have similar meanings, a unified language description is used; if the meanings of the multiple secret data are different, each secret data is described independently. Language description is implemented using formal grammar, and the formal grammar is selected from one of sequential grammar, tree grammar or graph grammar.

[0046] In step S103, the secret data set is described in language, the key features of the secret data are extracted, and the corresponding formal description structure is generated.

[0047] Through language description, complex secret data is abstracted into formalized structure for easy processing, and the relationship, hierarchy and importance between secret data are clear, which helps to design a more accurate secret sharing scheme. Among them, the representative features are extracted from the secret data set, such as the semantic content of the data, the data category, the correlation and dependency between the data, etc. These key features constitute the basic information of language description. When multiple secret data in the secret data set have similar meanings or similar functions, they are summarized into the same language description model to reduce redundancy and improve processing efficiency and description consistency. When the meanings of secret data are significantly different, independent language description is established for each secret data to facilitate targeted protection and management.

[0048] In step S104, parameters of the threshold secret sharing scheme are selected based on the formal description structure and the key features of the secret data, the total number of protocol participants n and the minimum number of shadow fragments m required for reconstruction of the secret data are determined, and the allocation manner of the secret data is selected as one of equal allocation and privileged allocation.

[0049] In the equal allocation manner, each protocol participant obtains a secret shadow fragment with equal rights, and in the privileged allocation manner, at least one protocol participant is designated as a privileged participant and is allocated a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction process of the secret data.

[0050] When the formal description structure is a tree structure, the secret data set is divided into multiple hierarchical sub-secret nodes, each sub-secret node corresponds to a part of the secret data set, the connection relationship between the sub-secret nodes represents the combination order of the parts of the secret data, and the sub-secret nodes of different levels are allocated to the protocol participants of the corresponding levels; when the formal description structure is a graph structure, the secret data set is divided into several secret parts and mapped to the nodes of the graph structure, each node corresponds to a part of the secret data set, the nodes are connected by undirected edges to represent the association relationship between the secret parts, and the secret parts corresponding to the nodes are allocated to different protocol participants as shadow fragments.

[0051] As an explanation, in the determination of the threshold parameters, the total number of protocol participants n is determined according to the number of nodes actually participating in the secret sharing and reconstruction in the system, including all trusted management entities or devices; the minimum number of shadow fragments m is the minimum number of shadow fragments required for successful reconstruction of the secret data, which satisfies m≤n, the size of m affects the data security and fault tolerance, the larger m is, the higher the security is, but the recovery threshold is also improved. Equal allocation means that all protocol participants obtain equal secret shadow fragments without special privileges, which is suitable for environments with equal rights and same responsibilities. Privileged allocation means that in practical applications, some participants need to have additional secret shadow fragments due to the importance of their responsibilities or special privileges, to ensure that they cannot be replaced in the reconstruction process of the secret data, so as to realize hierarchical management, privilege control and security policy customization.

[0052] In the application of tree structure, the secret data set is divided into multiple hierarchical sub-secret nodes, each node corresponds to a part of the secret data, and the connection between the nodes represents the combination and inheritance order of the secret data; the sub-secret nodes of different levels are allocated to the protocol participants of the corresponding levels to realize hierarchical management and enhance the refinement of security policy; such hierarchical division facilitates the management of complex secret data and access rights, and is suitable for scenes with rigorous organizational structure.

[0053] In the application of graph structure, the secret data is divided into multiple secret parts, which are mapped to the nodes of the graph, and the nodes are connected by undirected edges, representing the association and dependence between the secret parts; the shadow fragments are assigned to different protocol participants based on the graph structure, supporting multi-path and multi-role data recovery methods.

[0054] In step S105, the threshold secret sharing scheme is executed to divide the secret data set into n shadow fragments according to the formal description structure, and the n shadow fragments are respectively assigned to n protocol participants.

[0055] The threshold secret sharing scheme is executed in a hierarchical multi-level structure environment, and the protocol participants are distributed on multiple levels including organization level, fog computing level and cloud level. The protocol participants of each level obtain the secret shadow fragments of the corresponding level, thereby realizing the distribution and management of the secret data in the multi-level structure.

[0056] Exemplarily, when the secret data is image data, a language description based graph threshold secret sharing scheme is executed, including: generating a formal graph structure according to the key features of the image data, dividing the image data into several shadow fragments, each of which corresponds to a node in the graph structure; determining the minimum number of shadow fragment combinations required to reconstruct the image data through the association relationship between the nodes in the graph structure, and assigning the shadow fragments to different protocol participants, so that when no less than the minimum number of combinations of shadow fragments are collected, the original image data can be recovered.

[0057] In step S106, when the secret data needs to be recovered, no less than m shadow fragments are collected, and the original secret data is reconstructed according to the formal description structure of at least m shadow fragments.

[0058] Exemplarily, assuming that the secret data is divided into 9 shadow fragments, and the minimum reconstruction threshold m is set to 3, in the data recovery stage, at least 3 different shadow fragments (such as shadow fragments numbered 2, 5 and 9) need to be collected. According to the language description structure before, the 3 shadow fragments are mathematically operated and logically combined, and the complete secret data is recovered by using the threshold secret sharing algorithm (such as Shamir algorithm). For example, for image data, the image parts corresponding to the 3 shadow fragments are fused to reconstruct the original complete image. Only when the number of collected shadow fragments reaches or exceeds m, the recovered data can be guaranteed to be correct and reliable, ensuring the safe and reliable reconstruction of the data.

[0059] Based on the same idea, as Figure 2As shown, it is a structural block diagram of the intelligent algorithm center network data management system provided by an embodiment of the present application. The system comprises: an acquisition module 201, configured to acquire an original data set containing original information as input, wherein the original data set contains secret data to be hidden; an evaluation module 202, configured to evaluate the original data set, determine secret data to be hidden from the original data set, and obtain a secret data set; a language description module 203, configured to perform language description on the secret data set, extract key features of the secret data, and generate a corresponding formal description structure; a scheme selection module 204, configured to select parameters of a threshold secret sharing scheme based on the formal description structure and the key features of the secret data, determine the total number n of protocol participants and the minimum number m of shadow fragments required for reconstruction of the secret data, and select an allocation manner of the secret data as one of equal allocation and privileged allocation; a sharing execution module 205, configured to execute the threshold secret sharing scheme, divide the secret data set into n shadow fragments according to the formal description structure, and allocate the n shadow fragments to n protocol participants respectively; and a data recovery module 206, configured to collect no less than m shadow fragments when the secret data needs to be recovered, and combine the at least m shadow fragments according to the formal description structure to reconstruct the original secret data.

[0060] The specific details in the above system have been described in detail in the method part embodiment, and the undisclosed details can be referred to the content of the method part embodiment, and thus will not be described again.

[0061] The system improves the security of network data management, divides sensitive information into multiple shadow fragments through the threshold secret sharing technology, and can only reconstruct data when a predetermined number of shadow fragments are reached, greatly reducing the risk of data leakage; enhances the flexibility and refinement of data management, clearly defines and distinguishes the key features of different data through the language description method, making the sharing and management of data more accurate; improves the fault tolerance of the system, even if part of the shadow fragments are lost or damaged, data reconstruction can still be completed through other shadow fragments, significantly improving the reliability of data recovery; reduces the single point failure risk caused by centralized storage of data, and significantly improves the stability and continuity of data services of the intelligent algorithm center through the distributed shadow management strategy.

[0062] Based on the same idea, the present specification also provides an intelligent algorithm center network data management device, as shown in Figure 4

[0063] The intelligent algorithm center network data management device can be a terminal device or a server provided by the above embodiment.

[0064] ​The data management device of the AI center network can have a large difference due to different configurations or performances, and can include one or more processors 301, memories 302, and buses. The memories 302 can store one or more storage applications or data. The memories 302 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) and / or a cache memory, for example, a plug-in mobile hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like, which are equipped on an electronic device, and can further include a read-only storage unit. The applications stored in the memories 302 can include one or more program modules (not shown in the drawing), and such program modules include, but are not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or a combination thereof can include an implementation of a network environment. Further, the processor 301 can be configured to communicate with the memory 302 and execute a series of computer-executable instructions in the memory 302 on the data management device of the AI center network. The data management device of the AI center network can further include one or more power supplies 303, one or more wired or wireless network interfaces 304, one or more I / O interfaces (input / output interfaces) 305, one or more external devices 306 (for example, a keyboard) for communication, and can further communicate with one or more devices that enable a user to interact with the device, and / or any device that enables the device to communicate with one or more other computing devices (for example, a router, a network switch, and the like). Such communication can be performed through the I / O interface 305. Also, the device can communicate with one or more networks (for example, a local area network (LAN)) through the wired or wireless interface 304.

[0065] The processor 301 can be composed of an integrated circuit in some embodiments, for example, can be composed of a single packaged integrated circuit, or can be composed of a plurality of packaged integrated circuits with the same function or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and combinations of various control chips, etc. The processor 301 is the control unit of the electronic device, which connects various components of the entire electronic device through various interfaces and lines, and performs various functions of the processing device and processes data by running or executing programs or modules (for example, an AI center network data management program, etc.) stored in the memory 11 and calling data stored in the memory.

[0066] The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The bus is configured to enable connection and communication between the memory 302, the at least one processor 301, etc.

[0067] The power supply can be logically connected to the at least one processor 301 through a power management device, so as to realize functions such as charge management, discharge management, and power consumption management through the power management device. The power supply can also include one or more direct current or alternating current power supplies, a recharging device, a power supply fault detection circuit, a power supply converter or inverter, a power supply status indicator, etc. The electronic device 1 can also include various sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be described here.

[0068] Optionally, the processing device can also include a user interface, which can be a display (Display). Optionally, the user interface can also be a standard wired interface, a wireless interface. Optionally, in some embodiments, the display can be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED

[0069] (Organic Light-Emitting Diode, Organic Light Emitting Diode) touch screen, etc. The display can also be appropriately referred to as a display screen or a display unit, for displaying information processed in the electronic device 1 and for displaying a visualized user interface

[0070] Figure 3 Only the intelligent center network data management device with components is shown, and those skilled in the art can understand that, Figure 3 The structure shown does not constitute a limitation on the intelligent center network data management device, and can include fewer or more components than shown, or combine certain components, or different component arrangements.

[0071] In particular, in this embodiment, the intelligent center network data management device includes a memory, and one or more programs, wherein one or more programs are stored in the memory, and one or more programs can include one or more modules, and each module can include a series of computer executable instructions in the intelligent center network data management device, and is configured to execute the one or more programs by one or more processors, which include computer executable instructions for:

[0072] Obtain an original data set containing original information as input, the original data set containing secret data to be hidden;

[0073] Evaluate the original data set, determine secret data to be hidden from the original data set, and obtain a secret data set;

[0074] Language description is performed on the secret data set, key features of secret data are extracted, and a corresponding formal description structure is generated;

[0075] Based on the formal description structure and the key features of the secret data, parameters of a threshold secret sharing scheme are selected, the total number of protocol participants n and the minimum number of shadow fragments m required for reconstruction of the secret data are determined, and the allocation method of the secret data is selected as one of equal allocation or privileged allocation;

[0076] The threshold secret sharing scheme is executed, the secret data set is divided into n shadow fragments according to the formal description structure, and the n shadow fragments are respectively allocated to n protocol participants;

[0077] When the secret data needs to be recovered, no less than m shadow fragments are collected, and the original secret data is reconstructed according to the formal description structure at least m shadow fragments are combined.

[0078] Based on the same idea, the exemplary embodiments of the present application also provide a computer readable storage medium having a program product stored thereon capable of implementing the above-mentioned method of the present specification. In some possible embodiments, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program codes for causing a terminal device to execute the steps described in the above-mentioned “example method” section according to various example embodiments of the present disclosure when the program product is run on the terminal device.

[0079] Reference Figure 4 As shown, the program 400 for implementing the above-mentioned method according to the example embodiments of the present disclosure is described, which can adopt a portable compact disc read-only memory (CD-ROM) and includes program codes, and can be run on a terminal device, such as a personal computer. However, the program product of the present disclosure is not limited thereto, and in this document, the readable storage medium can be any tangible medium containing or storing a program, which can be used or combined with an instruction execution system, device or apparatus.

[0080] The program product can employ any combination of one or more computer-readable media. The computer-readable media can be a computer-readable storage medium or a computer-readable signal medium. The computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include the following: an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0081] The computer-readable signal medium can include a computer-readable storage medium that is propagated as a carrier wave. The computer-readable signal medium can further be any computer-readable medium that is not a storage medium. The computer-readable signal medium can be a computer-readable storage medium that is a propagated signal on a carrier wave.

[0082] The program code can be executed by one or more programmable processors, which can be implemented as one or more microprocessors, microcontrollers, digital signal processors, embedded processors, programmable logic devices, FPGAs, PLDs, or the like. The program code can be downloaded from a remote computer (for example, through the Internet) or can be uploaded from a local computer or memory external to the computer. The program code can be stored on a computer-readable storage medium, which can be any device or medium that can store or transfer program code. The computer-readable storage medium can be a computer program product. The computer-readable storage medium can be a non-transitory computer-readable storage medium. The computer-readable storage medium can be a computer-readable storage medium that is not a transitory propagating signal.

[0083] Those skilled in the art will easily understand, through the above description of the embodiments, that the example embodiments described herein can be implemented by software, or by software in combination with necessary hardware. Therefore, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.) or a network, and includes a number of instructions to make a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) execute the methods according to the example embodiments of the present disclosure.

[0084] Furthermore, the above-described figures are merely schematic illustrations of the processes included in the method according to the example embodiments of the present disclosure, and are not intended for limiting purposes. It is readily understood that the processes illustrated in the above-described figures do not indicate or limit the chronological order of these processes. In addition, it is also readily understood that these processes can be executed, for example, synchronously or asynchronously in a plurality of modules.

[0085] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. Indeed, according to the example embodiments of the present disclosure, the features and functionalities of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functionalities of one module or unit described above can be further divided into embodied by a plurality of modules or units.

[0086] Other embodiments of the present disclosure will be readily apparent to those skilled in the art upon considering the description hereof, prefaced by the conceptional drawings. The present application is intended to cover any variations, uses, or adaptations of the present disclosure following, in general, the principles of the present disclosure and including such departures from the present disclosure that come within known or customary practice in the art to which the present disclosure pertains. The specification and examples are to be regarded as illustrative only, and the true scope and spirit of the present disclosure are indicated by the appended claims.

[0087] It should be understood that the present disclosure is not limited to the precise structures herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the claims that follow.

Claims

1. A method for managing network data in an intelligent computing center, characterized in that, The method includes: Obtain the original dataset containing the original information as input, wherein the original dataset contains secret data to be concealed; Evaluate the original dataset, determine the secret data that needs to be hidden from the original dataset, and obtain the secret dataset; The secret dataset is described using language, key features of the secret data are extracted, and a corresponding formal description structure is generated. Based on the formal description structure and key features of the secret data, the parameters of the threshold secret sharing scheme are selected, the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction are determined, and the secret data allocation method is selected as either equal allocation or privileged allocation. The threshold secret sharing scheme is executed by dividing the secret dataset into n shadow segments according to the formal description structure, and then allocating these n shadow segments to n protocol participants respectively. When it is necessary to recover the secret data, at least m shadow fragments are collected, and the original secret data is reconstructed by combining at least m shadow fragments according to the formal description structure.

2. The intelligent computing center network data management method according to claim 1, characterized in that, The evaluation of the original dataset also includes: Extract the secret data that needs to be concealed from the original information dataset; and remove irrelevant data or insert the irrelevant data as noise data to interfere with the true meaning of the secret data.

3. The intelligent computing center network data management method according to claim 1, characterized in that, When the secret dataset contains multiple secret data, if the multiple secret data have similar meanings, they are described using a unified language; if the multiple secret data have different meanings, each of the secret data is described using an independent language. The language description is implemented using a formal grammar, which is selected from one of sequential grammar, tree grammar, or graphical grammar.

4. The intelligent computing center network data management method according to claim 1, characterized in that, Under the equal allocation method, each of the protocol participants receives an equal share of the secret shadow fragment; under the privileged allocation method, at least one protocol participant is designated as a privileged participant and allocated a privileged shadow fragment, so that the privileged participant is indispensable in the reconstruction of the secret data.

5. The intelligent computing center network data management method according to claim 1, characterized in that, The threshold secret sharing scheme is executed in a layered, multi-level structure environment. The protocol participants are distributed across multiple layers, including the organization layer, fog computing layer, and cloud layer. Each participant at each layer obtains a secret shadow fragment corresponding to that layer, thereby enabling the distribution and management of the secret data in the multi-layered structure.

6. The intelligent computing center network data management method according to claim 1, characterized in that, When the formal description structure is a tree structure, the secret dataset is divided into multiple hierarchical sub-secret nodes, each sub-secret node corresponding to a part of the secret dataset. The connection relationship between the sub-secret nodes represents the combination order of the secret data in each part, and the sub-secrets of different levels are assigned to the protocol participants of the corresponding levels. When the formal description structure is a graph structure, the secret dataset is divided into several secret parts and mapped to the nodes of the graph structure. Each node corresponds to a part of the secret dataset. The nodes are connected by undirected edges to represent the association relationship between the secret parts, and the secret parts corresponding to each node are assigned as shaded fragments to different protocol participants.

7. The intelligent computing center network data management method according to claim 1, characterized in that, When the secret data is image data, a language-described graph-based threshold secret sharing scheme is implemented, including: A formal graph structure is generated based on the key features of the image data, and the image data is divided into several shadow segments, each shadow segment corresponding to a node in the graph structure; The minimum number of shadow fragment combinations required to reconstruct the image data is determined by the relationships between nodes in the graph structure, and the shadow fragments are assigned to different protocol participants so that the original image data can only be recovered when at least the minimum number of shadow fragment combinations are collected.

8. A network data management system for an intelligent computing center, the system comprising: The acquisition module is used to acquire a raw dataset containing original information as input, wherein the raw dataset contains secret data to be concealed; An evaluation module is used to evaluate the original dataset, determine the secret data that needs to be hidden from the original dataset, and obtain the secret dataset. The language description module is used to describe the secret dataset in language, extract key features of the secret data, and generate a corresponding formal description structure. The scheme selection module is used to select the parameters of the threshold secret sharing scheme based on the formal description structure and key features of the secret data, determine the total number of protocol participants n and the minimum number of shadow fragments m required for secret data reconstruction, and select the secret data allocation method as either equal allocation or privileged allocation. A shared execution module is used to execute the threshold secret sharing scheme, divide the secret dataset into n shadow segments according to the formal description structure, and assign these n shadow segments to n protocol participants respectively; The data recovery module is used to collect no less than m shadow fragments when it is necessary to recover the secret data, and to reconstruct the original secret data by combining at least m shadow fragments according to the formal description structure.

Citation Information

Patent Citations

  • System or method for implementing forgotten rights on metadata-driven blockchains using secret sharing and consensus of reads

    CN114365133A

  • Data distributed storage method and system based on secret sharing technology

    CN119172077A